# indexed-btree npm supply-chain campaign bypasses npm's default-disabled install scripts via runtime prototype hook

> A family of malicious npm packages led by indexed-btree (impersonating sorted-btree) hides its loader in BTree.prototype.set, so it runs when an application uses the library rather than at install time, sidestepping npm 12's default disabling of lifecycle scripts. The payload fingerprints the host, reports to hardcoded Slack and Telegram channels, and pulls an encrypted second stage from an Ethereum Sepolia smart contract (EtherHiding).

- **Published:** 2026-10-06T00:00:00Z
- **Last reviewed:** 2026-10-06T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2969
- **ID:** TL-2026-2969
- **Severity:** HIGH
- **Category:** SUPPLY_CHAIN
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 22 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Checkmarx Zero (published 2026-09-17) and ReversingLabs (2026-10-06) describe a campaign in which the npm package indexed-btree mimics the legitimate sorted-btree library. Unlike typical npm malware, the package contains no preinstall or postinstall script and has a clean package.json, so it is unaffected by npm 12 (released 2026-07-08), which turns off dependency lifecycle scripts and implicit node-gyp builds by default (allowScripts defaults to off). Instead the loader is embedded in BTree.prototype.set, a core method applications call during normal use. Per reporting, the loader checks whether the key equals 100 and then launches an obfuscated JavaScript file (sharedLoad.min.js) from the package as a detached process, so the payload runs with the full privileges and network access of the host application. The package was backed by cover infrastructure: a GitHub repository (INDEXED-BTREE/indexed-btree) with a plausible commit history and a fabricated developer profile with an AI-generated photograph.

The first-stage loader fingerprints the host (OS/architecture, hostname, CPU, memory; the sibling mutex-forge loader also collects platform, release and uptime) and posts the data to a hardcoded Telegram chat (-1003952553968) and Slack channel (C0B8XPGCKQS) using bot tokens shipped inside the file. It then connects to an Ethereum Sepolia testnet smart contract (0xE390863Dac96a7118C71227C2b099B50cF602D31), using the contract as a pointer/dead-drop for an encrypted second-stage payload, an approach (EtherHiding) that is more resilient to takedown than a conventional C2 domain. Per analysis of the earlier related package mutex-forge, the payload is AES-GCM encrypted with a key derived via ECDH from an X25519 keypair, written to disk and executed, and a persistent command channel is kept by polling the Slack API for attacker commands. Researchers note the same contract and the same Slack/Telegram identifiers appeared in mutex-forge, linking the two clusters.

Scale: indexed-btree reportedly reached about 2 million weekly downloads before detection, and the family of roughly ten related packages (ordered-kv-index, btree-leaderboard, priority-slot-queue, btree-range-store, btree-core, btree-time-index, btree-lru-cache, neighbor-key-map, sliding-score-window) was tied to over 5 million cumulative downloads over roughly eleven weeks. Checkmarx cautions that download counts are not a count of compromised hosts, because execution requires application code to actually call the hooked method. The operator reportedly collected about 109 ETH (about EUR 231,000 / USD 265-300K) through the contract. As of late reporting the campaign was described as ongoing with C2 still operational and the GitHub repository still online; packages were reported removed. No threat actor has been named.

Note: the attacker-embedded Slack and Telegram bot tokens and RPC API keys disclosed by researchers are deliberately not reproduced here; only non-secret identifiers are listed as IOCs.

## MITRE ATT&CK

- T1195.002 Compromise Software Supply Chain
- T1587.001 Malware
- T1608 Stage Capabilities
- T1059.007 JavaScript
- T1036.005 Match Legitimate Resource Name or Location
- T1027 Obfuscated Files or Information
- T1140 Deobfuscate/Decode Files or Information
- T1082 System Information Discovery
- T1102.002 Bidirectional Communication
- T1071.001 Web Protocols
- T1573.001 Symmetric Cryptography
- T1567 Exfiltration Over Web Service
- T1480 Execution Guardrails
- T1070.004 Indicator Removal: File Deletion
- T1583.006 Acquire Infrastructure: Web Services
- T1585.001 Establish Accounts: Social Media Accounts
- T1657 Financial Theft

## Sources

- [Dependency installation security measure already defeated on npm (ReversingLabs)](https://www.reversinglabs.com/blog/npm-dependency-installation-security-measure-defeated)
- [npm btree malware campaign affects millions of downloads, no need for install script (Checkmarx Zero)](https://checkmarx.com/zero-post/npm-btree-malware-campaign-affects-millions-of-downloads-no-need-for-install-script/)
- [Malicious B-Tree npm Package Accumulates Millions of Downloads (SecurityWeek)](https://www.securityweek.com/malicious-b-tree-npm-package-accumulates-millions-of-downloads/)
- [New npm Threat Bypasses Install Script Protections (DevOps.com)](https://devops.com/new-npm-threat-bypasses-install-script-protections/)
- [indexed-btree npm malware runtime trigger (Hive Security)](https://hivesecurity.gitlab.io/blog/indexed-btree-npm-malware-runtime-trigger)
- [Malicious npm Package With 2 Million Downloads Hides Malware in Runtime Code (Cryptika)](https://www.cryptika.com/malicious-npm-package-with-2-million-downloads-hides-malware-in-runtime-code/)
- [npm 12 disables install scripts by default (The Hacker News)](https://thehackernews.com/2026/07/npm-12-disables-install-scripts-by.html)
- [OSV MAL-2026-13955: Malicious code in mutex-forge (npm)](https://osv.dev/vulnerability/MAL-2026-13955)
- [CSA research note: npm runtime execution supply chain](https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/09/CSA_research_note_npm_runtime_execution_supply_chain_20260923-csa-styled.pdf)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2969
